#log4shell
Happy Log4Shell Anniversary 😅
December 9, 2024 at 5:05 PM
There are only two bug classes left: complexity and memory safety.

CurveBall (CVE-2020-0601)? Complexity.
BigSig (CVE-2021-43527)? Memory safety.
Log4Shell (CVE-2021-44228)? Complexity.
BlueKeep (CVE-2019-0708)? Memory safety.

Heartbleed looks like memory safety, but it's actually complexity.
April 15, 2026 at 7:08 PM
I never imagined GitHub would ask me to speak about #Log4Shell.
But it happened.

@github.com asked me to share the story as I lived it, for the benefit of users of #opensource. How could I say no?

I hope it helps build a more secure future.
No more Log4Shell.

#java
github.com GitHub @github.com · Oct 20
The internet was on fire. 🔥
One small library affecting billions of systems.
Log4Shell was the biggest security vulnerability of all time.

Now, Log4J maintainer, Christian Grobmeier tells us what it felt like inside the flames 👉 github.blog/open-source/...
October 20, 2025 at 8:01 PM
You still have an unauthenticated endpoint. It’s been 5 years. Please patch the log4shell cve. No, storing the username and password in a base64 encoded cookie is not an appropriate session management strategy.
May 22, 2026 at 5:29 AM
The internet was on fire. 🔥
One small library affecting billions of systems.
Log4Shell was the biggest security vulnerability of all time.

Now, Log4J maintainer, Christian Grobmeier tells us what it felt like inside the flames 👉 github.blog/open-source/...
October 20, 2025 at 6:37 PM
When your dad breaks Minecraft.

And the internet.

Watch the full interview about the biggest security vulnerability of all time 👉 https://github.blog/open-source/inside-the-breach-that-broke-the-internet-the-untold-story-of-log4shell/?utm_source=social&utm_medium=social&utm_campaign=minecraft
November 12, 2025 at 11:21 AM
Exploiting Log4Shell: How Log4J Applications Were Hacked
Exploiting Log4Shell: How Log4J Applications Were Hacked
A Deep Dive into the Log4Shell Vulnerability [CVE-2021–44228]
infosecwriteups.com
March 19, 2025 at 5:24 AM
I can well imagine the cybersecurity team at Flock has done a threat modeling scenario where a supply chain attack injecting log4j versions which are vulnerable to log4shell has been documented as a particular and specific kind of “bad day” for them
September 18, 2026 at 4:44 PM
this is an interesting question. i don't think there's been anything on the scale of log4shell/heartbleed yet, in terms of real world impact. there's been serious vulnerabilities that haven't really been huge impact wise. maybe BatBadBut?
Has there ever been a truly critical memory safety vulnerability in widely used Rust code?

Excluding codegen bugs (like the one in wasmtime), since unfortunately the safety guarantees of Rust only extend to actual rust code, not code generated by rust code.
October 21, 2025 at 5:16 PM
「Log4Shellの脆弱性を利用してLog4Shellの脆弱性を修正する攻撃」とかあってもうめちゃくちゃだった
July 16, 2025 at 3:41 AM
The U.S. and its Five Eyes intelligence partners have released a list of 2023's most exploited vulnerabilities:

MOVEit and Log4Shell *still* in the top 15.

https://www.cisa.gov/sites/default/files/2024-11/aa24-317a-2023-top-routinely-exploited-vulnerabilities.pdf
November 12, 2024 at 5:22 PM
Classy Lady ☕
May 25, 2026 at 6:56 AM
December 10, 2024 at 11:19 PM
fuck ‘em all! 😅😭
October 28, 2023 at 1:10 AM
being reminded of the log4shell attack today
September 22, 2025 at 11:40 AM
Write your developer horror story in 5 words or less. 🎃

We'll go first: Remote code execution.

https://github.blog/open-source/inside-the-breach-that-broke-the-internet-the-untold-story-of-log4shell/

October 31, 2025 at 11:45 AM
really aggravating to see articles like this that could have been interesting, but give a very shallow analysis and are full of chatgpt tells github.blog/open-source/...
Inside the breach that broke the internet: The untold story of Log4Shell
Log4Shell proved that open source security isn't guaranteed and isn’t just a code problem.
github.blog
October 23, 2025 at 8:56 AM
Only a few days ago, I joined Abby and Felix Reda on the Github Podcast—to talk about funding in #opensource that we have received from @sovereign.tech

podcasts.apple.com/de/podcast/f...

#java #log4j #log4shell
From Log4Shell to the Sovereign Tech Fund: Lessons in Open Source Sustainability
Podcast-Folge · The GitHub Podcast · 21.10.2025 · 31 Min.
podcasts.apple.com
October 25, 2025 at 5:46 AM
As a fellow maintainer of an open source project, this is an intense and somewhat scary read. Thanks to @grobmeier.de for being so open to talk about what he experienced and @github.com for initiating their Secure Open Source Fund!

github.blog/open-source/...
Inside the breach that broke the internet: The untold story of Log4Shell
Log4Shell proved that open source security isn't guaranteed and isn’t just a code problem.
github.blog
October 21, 2025 at 5:11 AM
This pattern shows up across the industry, not just in JavaScript. For example, after Log4Shell, additional CVEs were reported as the community examined the original fix.

Additional disclosures can be frustrating, but they are generally a sign of a healthy response cycle.
December 11, 2025 at 8:51 PM
It took one global incident for the world to see how vital open source maintainers are.

In this episode of The GitHub Podcast, we talk to Christian Grobmeier about the aftermath of Log4Shell and what it means for the future of open source funding. the-github-podcast.simplecast.com/episodes/fro...
From Log4Shell to the Sovereign Tech Fund: Lessons in Open Source Sustainability | The GitHub Podcast
In this episode of the GitHub Podcast, Abby sits down with Felix Reda, Director of Developer Policy at GitHub, and Christian Grobmeier, a longtime Log4J maintainer, to reflect on the aftermath of the ...
the-github-podcast.simplecast.com
October 22, 2025 at 10:48 AM
Sorry, I don't have a customer with the email "${jndi:ldap://log4shell-generic-K1govtBoVa8bHdMMpUUI${lower:ten}.w.nessus.org/nessus}" raise ArgumentError, "invalid name: #{str.dump}"
February 4, 2025 at 6:24 PM
Watch our full interview with Christian Grobmeier here 👇 youtu.be/t74ClffSUW0?...
The Untold Story of Log4j and Log4Shell | Christian Grobmeier | GitHub
YouTube video by GitHub
youtu.be
October 22, 2025 at 12:02 PM